Windows 7 Forums

Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: MSE took so long to remove 3 types of Sirefef

15 Jun 2012   #1
zeamann

Windows 7 Ultimate x64 SP1
 
 
MSE took so long to remove 3 types of Sirefef

Greetings Sires and mi Ladies,

Please provide your expert advice on this:

My Dad's laptop keep restarting after a BSOD but was okay after opting for "last known good configuration" by pressing F8 BUT! It restarted with MSE's warning that PC is infected, so I didn't immediately clicked MSE's "clean button" but opened MSE's GUI and ran a full scan. This scan of course already took almost 1 hour so I went to sleep. I woke up later at around 1640 hours and found that MSE already finished scanning and got the following infections to which I immediately clicked "clean computer"
  1. TrojanDropper:Win32/Sirefef.B
  2. Trojan:WinNT/Sirefef.J
  3. Trojan:Win32/Sirefef.AH

The time now is 1918 hours and MSE is still running, trying to remove the infection. I am beginning to think that MSE (because it is not yet updated) will not be able to remove these infections. I will leave it till 2200 hours before forcing shut down but in the mean time please advise. Any tips and tricks and views and opinions including everything in between are all welcomed.

regards to you all and God Bless,

Zeamann.


My System SpecsSystem Spec
.

15 Jun 2012   #2
Borg 386

Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1 Pro
 
 

From a security point of view, when a system is compromised by a rootkit, the safest option is to do a clean install. That would be the recommended action being that you have 3 rootkits. Even if you remove the rootkits, it's doubtful your PC can be trusted again and any remnants of the virus can cause problems down the road.

Clean Install Windows 7

Technical information:

http://www.microsoft.com/security/po...64%2FSirefef.W

If this is not an option:

Eset has a removal tool which may work:

http://www.eset.eu/encyclopaedia/win...-trojandropper

Another option is Windows Defender Offline:

http://windows.microsoft.com/en-US/w...fender-offline

Depending on the variant you have, it may remove the infection. However, the newer versions of this rootkit are tougher to remove. You can also try TDSSKiller.

There has been a new tool released which has had mixed success at removing this bug:

http://blog.webroot.com/2011/08/03/n...ccess-goodbye/

If this does not remove it, please see this link for manual removal of this bug:

How to Remove TR/Sirefef.BV.2 If Combofix & TDSSKiller Won’t Work? - Malware Removal - Malware Info
My System SpecsSystem Spec
15 Jun 2012   #3
zeamann

Windows 7 Ultimate x64 SP1
 
 

Quote   Quote: Originally Posted by Borg 386 View Post
From a security point of view, when a system is compromised by a rootkit, the safest option is to do a clean install. That would be the recommended action being that you have 3 rootkits. Even if you remove the rootkits, it's doubtful your PC can be trusted again and any remnants of the virus can cause problems down the road.

Clean Install Windows 7

Technical information:

Encyclopedia entry: Trojan:Win64/Sirefef.W - Learn more about malware - Microsoft Malware Protection Center

If this is not an option:

Eset has a removal tool which may work:

http://www.eset.eu/encyclopaedia/win...-trojandropper

Another option is Windows Defender Offline:

What is Windows Defender Offline?

Depending on the variant you have, it may remove the infection. However, the newer versions of this rootkit are tougher to remove. You can also try TDSSKiller.

There has been a new tool released which has had mixed success at removing this bug:

New Tool Released: Kiss (or Kick) ZeroAccess Goodbye « Webroot Threat Blog

If this does not remove it, please see this link for manual removal of this bug:

How to Remove TR/Sirefef.BV.2 If Combofix & TDSSKiller Won’t Work? - Malware Removal - Malware Info
Thank you so very much Borg for a very thorough guidance. I am going to try the clean install as I have backed up all critical personal files and/or documents.

Thank you again and God Bless,

Zeamann.
My System SpecsSystem Spec
.


15 Jun 2012   #4
Borg 386

Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1 Pro
 
 

That's the best course to take . One word of advice, scan all your personal files thoroughly before you put them back on the system to make sure they're not infected. You can submit files up to 32MB to VirusTotal, where they will be scanned by multiple AV's. Or scan your storage medium with MSE once it's back on your PC.

https://www.virustotal.com/
My System SpecsSystem Spec
17 Jun 2012   #5
zeamann

Windows 7 Ultimate x64 SP1
 
 

Quote   Quote: Originally Posted by Borg 386 View Post
That's the best course to take . One word of advice, scan all your personal files thoroughly before you put them back on the system to make sure they're not infected. You can submit files up to 32MB to VirusTotal, where they will be scanned by multiple AV's. Or scan your storage medium with MSE once it's back on your PC.

https://www.virustotal.com/
Thank you for the tip Borg. I did just what you mentioned but both on my and Dad's machines prior opening the external drive after backing files into it.

Thanks again and God Bless,
My System SpecsSystem Spec
Reply

 MSE took so long to remove 3 types of Sirefef




Thread Tools





Similar help and support threads
Thread Forum
Cannot remove folder - filename or extension too long
This happened on a Windows XP SP3 32-bit computer. I am trying to delete the backup files created by the Memeo program that comes with Seagate GoFlex Home NAS. I selected the root folder of the backup files and pressed delete, which started the deletion process of some 30 GB sized backup. After the...
General Discussion
Index - Add or Remove File Types
How to Add or Remove a File Type from the Index in Windows 7 and Windows 8 The Index keeps track of the files on your computer and stores information about the files, including the file name, date modified, and properties like author, tags, and rating. The index is used to make searching for...
Tutorials
Remove irrelevant fonts + font file types
How can I remove irrelevant fonts from my PC ie, I only want English language fonts In Win7 64 bit there are a lot of non English fonts. Choosing a font in programs is laborious when I have to scroll thru a lot of irrelevant fonts.eg, "Batang Regular" cannot be deleted I can copy it to...
General Discussion
Sirefef!GenC troubling me
Hey there, I've got some serious trouble with Sirefef. It's been shutting down my computer and also blocking my internet access, so I'm kinda f**ked up. Norton seems to be unable to find and shut down the virus. Sometimes the virus causes a crash so the OS rollbacks and it goes all over. I tried...
System Security
Sirefef Removal!
Help guys, BitDefender just alerted me about being infected by the Sirefef trojan. These are the two particular variants BitDefender can't seem to remove: *Sirefef.A - C:/Windows/System32/services.exe *Sirefef.GY - C:/Windows/Installer/{84d3bf12-3c1a-e026-8b4e-76a071be099b}/U/00000004.@ Any...
System Security
How to remove Sirefef.(ending) from laptop hard drive
Alright; Major problem with my laptop. I got the Sirefef.P, .AP and .F virus on my laptop hard drive. I guess I didn't act fast enough and it pretty much crashed my hard drive. I can boot up into BIOS, after BIOS I have the choice of booting into Win 7 or Win 8 (I partitioned my drive so I...
System Security

Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd

All times are GMT -5. The time now is 18:28.

Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App